Required password length

Unanswered Question
Sep 16th, 2010

A year ago our company had a security audit, one of the items listed is the password for the 4240 did not meet the "password shall be a minimum of six characters" requirement. The documentation for 7.0 clearly states that you will be required to change password the first time you login and the password will be a minimum of 8 characters.

My question is did this change in some version? if so which version? If this is the way it has always been any idea where I can find documentation to prove it to the auditors?

Thanks

-Randy.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Allen P Chen Thu, 09/16/2010 - 10:46

Hello,

According to the IPS documentation, the requirement of 8 characters minimum for the password can be found on all versions all the way back to IPS version 4.x:

Step 2 You are prompted to change the default password.

Passwords must be at least eight characters long and be strong, that is, not be a dictionary word.

http://tinyurl.com/2cg7g63

Here is link to all the "Install and Upgrade Guides" for IPS versions from 4.x to the latest 7.x:

http://tinyurl.com/2444jwt

The 8 character minimum for the password is mentioned under "Initializing the sensor" in all versions.

Hope that helps!

Actions

This Discussion